ai-product-manager-playbook

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk AI product management playbook made of markdown guidance and templates, with one privacy caution around using production data for evaluations.

Install appears reasonable for a documentation/template skill. Before using its evaluation or telemetry workflows, review and redact real user queries, production data, and feedback logs, especially if they may contain personal, confidential, or regulated information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The guidance explicitly recommends using real-world user queries and production data for evaluations without any accompanying privacy, consent, minimization, or de-identification safeguards. In an AI PM playbook, that omission can lead teams to reuse sensitive production data in eval pipelines, exposing personal, confidential, or regulated information to reviewers, vendors, or secondary models.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal